August 4, 2026
Permissions: Controlling Which Customers an Agent Can Act For
3 MIN READ
Every sales agent has permissions that decide which of your customers they may act for. This is the most important setting in the app: it is what keeps a rep from ordering in the name of an account that is not theirs. Permissions are set per agent, take effect immediately, and are enforced on every request — not just in the customer list an agent sees. An agent who knows another customer's details still cannot act for them if permissions do not allow it.
Allow All Customers
The agent may act for any customer in your shop. This suits small teams where every rep handles every account, and it is the simplest way to test the app after installing it. It is the wrong setting for a larger team, or wherever reps have defined territories, because it gives every rep visibility of your entire customer base.
Specific Customers
The agent may act only for the customers you list. This is the most precise mode and the right one for a rep with a named account list. It requires maintenance: when an account is reassigned, you have to update the list. That is a fair trade for high-value accounts, and unmanageable if your rep handles hundreds of customers.
Specific Companies
Available on Shopify Plus, where your B2B customers are organised into companies. The agent may act for every contact of the companies you list. Useful when a rep owns a relationship with a business rather than with individual people at it — a new contact added to that company becomes available to the rep automatically, with no permission change needed.
By Tag
The agent may act for any customer carrying one of the tags you specify. This is usually the best option for a team of any size, because it makes permissions a property of your customer data rather than a list you maintain in a second place. Tag your customers by region, segment or route once, and reps inherit the right access. It also scales cleanly: a new customer tagged on creation is immediately available to the right rep, without anyone opening the app.
Choosing an Approach
For a shop with two or three reps who all handle everything, allow all customers and move on. For territory-based teams, use tags. Decide on a tagging scheme first — north, south, west, or key-account and standard — and apply it to your customers before configuring agents. For a small number of high-value named accounts, list the customers explicitly. On Plus, prefer companies over individual customers where your reps own the company relationship. The modes are per agent, so you can mix them: two reps on tags, one key-account manager on an explicit list.
How Enforcement Works
Permissions are checked at two points: when the agent browses or searches for customers, and again when they actually start a session. The second check is the one that matters — it means permissions cannot be bypassed by guessing or reusing a link. Changes apply immediately, including to agents who are signed in. If you remove an agent's access to a customer while they have an active session with that customer, the next action they take will be refused.
Reviewing Permissions
Permissions drift as teams and territories change. Set a recurring reminder — quarterly is enough for most shops — to open the agent list and confirm each rep still has the access they should. Pair this with the consent records on your customers, which name the agent who first acted for each of them. If a rep appears on accounts outside their expected territory, that is worth a conversation, and it is visible without asking anyone.